Reco Raises $55 Million to Lock Down AI Agents in the Enterprise
AT&T-backed Reco is betting that securing autonomous software identities and permissions is the next mandatory layer of enterprise infrastructure — not a nice-to-have.
The money flowing into AI infrastructure has, until recently, pooled almost entirely around foundation models and inference compute. Reco's $55 million financing round — announced September 29, 2026, with AT&T among the backers — signals that the next tranche is going somewhere else: the controls layer sitting between autonomous agents and everything they can touch inside an enterprise.
The Problem Reco Is Selling Against
AI agents are not users. They don't log in once, do a task, and close a browser tab. They hold persistent identities, accumulate permissions across systems, and execute sequences of actions — often without a human reviewing each step. That operational profile is exactly what enterprise security tooling was not designed to handle. Traditional identity and access management was built for people. Agents break the assumptions baked into those systems.
Reco's product targets precisely this gap: agent identities, permissions, and activity across enterprise environments. The pitch is that you cannot manage what you cannot see, and right now most organizations deploying agents have limited visibility into what those agents are credentialed to do — let alone what they are actually doing at any given moment.
Why AT&T's Participation Is the Tell
Venture rounds in security startups are common enough to be noise. What makes this one worth parsing is the strategic character of AT&T's involvement. A carrier of AT&T's scale operates enterprise infrastructure at a scope that makes agent-security exposure a first-order operational concern, not a theoretical one. When an organization of that size backs a startup in this space, it is rarely a purely financial bet — it is a signal about where they see their own vendor stack needing to evolve.
For Reco, that backing does something beyond the balance sheet. It provides a reference point for enterprise sales conversations where procurement teams want proof that the problem being solved is real and that the solution has been stress-tested against production-scale environments.
The Broader Shift This Round Reflects
Reco's raise was reported among a cluster of AI-security transactions on the same day — itself a data point. Capital is beginning to concentrate around autonomous software controls in the same way it concentrated around cloud security a decade ago, initially as a specialized concern and then as table stakes for any serious enterprise deployment.
The pattern is familiar: a new compute paradigm gets adopted fast, security gets bolted on late, and then a wave of purpose-built tooling emerges to close the gap between deployment reality and risk tolerance. Agents are now inside the perimeter. The gap-closing is underway.
$55 million is not a moonshot number — it is a scaling number. It suggests Reco has enough product-market signal to justify building go-to-market and expanding coverage, not enough to suggest anyone believes this problem is solved. That is probably the honest framing: agent security is an early-stage discipline chasing a fast-moving target, and the companies building in this space are writing the playbook in real time.
What Comes Next
The bigger shift this round names is structural. Enterprise AI adoption is moving from pilots to production, and production deployments carry accountability that pilots do not. When an agent makes a mistake — accesses data it shouldn't, executes an action without authorization, or gets compromised — someone is responsible. Legal, compliance, and board-level pressure is pushing organizations to answer the question they avoided during the pilot phase: how do we actually govern these things?
Reco is positioning itself as the answer to that question, specifically at the identity and permission layer. Whether the market consolidates around a handful of dedicated agent-security vendors or whether this capability gets absorbed into existing identity platforms is still an open question. What is no longer open is whether the category exists. The capital — and the backers writing the checks — have settled that.
